PT-2022-17063 · Cwp · Cwp

Published

2022-07-07

·

Updated

2023-01-24

·

CVE-2022-25047

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions CWP version 0.9.8.1126
Description The password reset token is generated using known or predictable values.
Recommendations For CWP version 0.9.8.1126, consider disabling the password reset feature until a patch is available to prevent potential exploitation. Restrict access to the password reset functionality to minimize the risk of unauthorized access. Avoid using the password reset token in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2022-25047

Affected Products

Cwp